# Security Vulnerability Report

> Respond to security vulnerability reports. Use when a researcher reports a security issue or asks about bug bounty policy.

- Skill: `majiayu000/security-vulnerability-report` (Agent Skill, multi-file: 2 files)
- Install (CLI): `npx skillmds add majiayu000/security-vulnerability-report`
- Raw SKILL.md: https://api.skillmd.com/api/skills/majiayu000/security-vulnerability-report/raw
- Safety review: pending
- Works with: Claude Code, Claude.ai, OpenAI Codex
- Category: Security
- Author: majiayu000 (https://skillmd.com/u/majiayu000)
- Updated: 2026-09-09
- Page: https://skillmd.com/skills/majiayu000/security-vulnerability-report

---

# Security Vulnerability Report

## Response Patterns (from samples)

Common openings:
- "No worries! Thanks for your concern!"
- "Hey Kiran,"
- "Hey Simon,"

Common core lines:
- ">>"
- ">"
- "Thanks for the heads up! We'll look into this ASAP."

Common closings:
- "Thanks for the heads up! We'll look into this ASAP."
- "Thanks for the heads up!"
- "Best,"

## Phrases That Work (4-gram frequency)

- "for the heads up" — 13 (40.6%)
- "thanks for the heads" — 12 (37.5%)
- "the heads up we'll" — 6 (18.8%)
- "heads up we'll look" — 6 (18.8%)
- "up we'll look into" — 6 (18.8%)
- "we'll look into this" — 6 (18.8%)
- "look into this asap" — 5 (15.6%)
- "on sun jan 25" — 2 (6.3%)
- "sun jan 25 2026" — 2 (6.3%)
- "jan 25 2026 at" — 2 (6.3%)

## Tone Guidance (observed)

- Openings trend toward: "No worries! Thanks for your concern!"
- Closings often include: "Thanks for the heads up! We'll look into this ASAP."

## What NOT To Do

- Don't introduce policy details that are not present in the verified response lines above.
- Don't paraphrase or reframe the customer's question in a way that changes meaning.
- Don't add refund/discount promises unless they appear in the extracted responses for this topic.

## Validation

Draft must:
- [ ] Include at least one of the required phrases from the validation block
- [ ] Stay consistent with the observed response patterns above
- [ ] NOT introduce policy details that are not present in the verified response lines above.
